Candidate: CVE-2016-7498 PublicDate: 2016-09-27 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7498 http://www.openwall.com/lists/oss-security/2016/09/21/1 Description: OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression. Ubuntu-Description: Notes: ratliff> Note from Debian: Relates to OSSA-2015-017 (CVE-2015-3280) ratliff> which was fixed and reintroduced with 13.0.0 and refixed in 13.1.0. Bugs: Priority: medium Discovered-by: Rajesh Tailor Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_nova: upstream_nova: released (2:13.1.0-1) precise_nova: ignored (reached end-of-life) precise/esm_nova: DNE (precise was needs-triage) trusty_nova: not-affected (1:2014.1.5-0ubuntu1.6) trusty/esm_nova: DNE (trusty was not-affected [1:2014.1.5-0ubuntu1.6]) vivid/stable-phone-overlay_nova: DNE vivid/ubuntu-core_nova: DNE xenial_nova: not-affected (2:13.1.1-0ubuntu1) esm-infra/xenial_nova: not-affected (2:13.1.1-0ubuntu1) yakkety_nova: not-affected zesty_nova: not-affected devel_nova: not-affected